CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,144 vulnerabilities with CWE-22
CVE-2024-42501 HIGH
Aruba OS <= 10.6.0.2, <= 10.6.0.0, <= 10.4.0.0, <= 8.10.0.13, <= 8.12.0.0, <= 8.12.0.1 - Authenticated Path Traversal
CVSS 7.2
CVE-2024-47049 HIGH
czim/file-handling <1.5.0, <2.3.0 - SSRF & Path Traversal
CVSS 8.2
CVE-2024-44190 MEDIUM
macOS < 13.7, < 14.7, < 15 - Unprotected User Data Exposure via Path Handling Issue
CVSS 5.5
CVE-2024-44167 MEDIUM
iPadOS < 18.0 - Path Traversal and Arbitrary File Write
CVSS 5.5
CVE-2024-27869 MEDIUM
iPadOS < 18.0 - Unauthenticated Screen Recording Without Indicator
CVSS 5.5
CVE-2024-8752 HIGH
WebIQ 2.15.9 - Path Traversal
CVSS 7.5
CVE-2024-8778 MEDIUM
OMFLOW 1.1.6.0-1.2.1.2 - Path Traversal via Download Functionality
CVSS 6.5
CVE-2024-8876 MEDIUM
xiaohe4966 TpMeCMS < 1.3.3.2 - Path Traversal via Lang Argument
CVSS 4.3
CVE-2024-8875 MEDIUM
wcms < 0.3.2 - Path Traversal via /wex/finder.php p Parameter
CVSS 5.4
CVE-2024-8865 LOW
composio < 0.5.8 - Path Traversal via File Parameter in API Download
CVSS 3.5
CVE-2024-8782 MEDIUM
JFinalCMS < 1.0 - Path Traversal via /admin/template/edit name Parameter
CVSS 6.3
CVE-2024-38816 HIGH
Spring WebMvc.fn and WebFlux.fn - Path Traversal via Static Resource Handling
CVSS 7.5
CVE-2024-7961 CRITICAL
Rockwell Automation Pavilion8 < 6.0 - Path Traversal and Remote Code Execution
CVSS 9.8
CVE-2024-8707 MEDIUM
Yunke Online School System <3.0.6 - Path Traversal
CVSS 4.3
CVE-2024-8706 MEDIUM
JFinalCMS <20240903 - Path Traversal
CVSS 4.3
CVE-2024-8694 LOW
JFinalCMS <20240903 - Path Traversal
CVSS 3.8
CVE-2024-7609 HIGH
Vidco VOC TESTER < 12.34.8 - Path Traversal
CVSS 7.5
CVE-2024-45593 CRITICAL
Nix 2.24.0-2.24.5 - Path Traversal and Arbitrary File Write via NAR Unpacking
CVSS 9.0
CVE-2024-21753 MEDIUM
FortiClientEMS 1.2.1-1.2.5 - Path Traversal and Limited File Read/Write via HTTP Requests
CVSS 5.5
CVE-2024-44867 HIGH
phpok v3.0 - Path Traversal and Arbitrary File Read via /autoload/file.php
CVSS 7.5
CVE-2024-37728 HIGH
OfficeWeb365 <8.6.1.0 - Info Disclosure
CVSS 7.5
CVE-2024-0067 MEDIUM
AXIS OS - Path Traversal via VAPIX API ledlimit.cgi
CVSS 4.3
CVE-2024-44720 HIGH
SeaCMS v13.1 - Path Traversal and Arbitrary File Read via admin_safe.php
CVSS 7.5
CVE-2024-8585 MEDIUM
Orca HCM < 11.0 - Authenticated Path Traversal via File Download Parameter
CVSS 6.5
CVE-2024-40712 HIGH
Veeam Backup & Replication <= 12.2.0.334 - Local Privilege Escalation via Path Traversal
CVSS 7.8
Details
Vulnerabilities 9,144
Exploit Likelihood High